Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
{ "versions": [ { "introduced": "5.0.0" }, { "fixed": "5.76.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28154.json"